-
-
Notifications
You must be signed in to change notification settings - Fork 4.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vulnerability in gulp 4.0.2 #2424
Comments
Related: isaacs/node-mkdirp#11 related: dominictarr/rc#114 |
and Path
|
Once mkdirp updates, the dependency will be pulled in automatically since we use semver - there isn't really anything actionable for us to do about this. Run FWIW these |
Your npm audit gives no context and you probably need to look at using a better tool. Like contra said, these don't effect us. In fact, minimist would only be used if you were directly running those dependencies as a command line tool, which you aren't when you are using gulp. |
The minimist needs to upgrade to >= 1.2.2
├─┬ [email protected]
│ └─┬ [email protected]
│ └─┬ [email protected]
│ └─┬ [email protected]
│ └─┬ [email protected]
│ ├─┬ [email protected]
│ │ └──
[email protected]
│ └─┬ [email protected]
│ └──
[email protected]
Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7598
The text was updated successfully, but these errors were encountered: